2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-9486On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account...
CVE-2016-9485On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account...
CVE-2016-9484The generated PHP form code does not properly validate user input folder directories, allowing a remote unauthenticated ...
CVE-2016-9483The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download...
CVE-2016-9482Code generated by PHP FormMail Generator may allow a remote unauthenticated user to bypass authentication in the to acce...
CVE-2016-6578HIGH8.8CodeLathe FileCloud, version 13.0.0.32841 and earlier, contains a global cross-site request forgery (CSRF) vulnerability...
CVE-2016-6567SHDesigns' Resident Download Manager provides firmware update capabilities for Rabbit 2000/3000 CPU boards, which accord...
CVE-2016-6566The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the...
CVE-2016-6565The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cs...
CVE-2016-6564Android devices with code from Ragentek contain a privileged binary that performs over-the-air (OTA) update checks. Addi...
CVE-2016-6563Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D...
CVE-2016-6562On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificat...
CVE-2016-6559Improper bounds checking of the obuf variable in the link_ntoa() function in linkaddr.c of the BSD libc library may allo...
CVE-2016-6558A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and po...
CVE-2016-6557In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface ...
CVE-2016-6554Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1...
CVE-2016-6553Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses non-random default credentials of: admin:admin and local...
CVE-2016-6552Green Packet DX-350 uses non-random default credentials of: root:wimax. A remote network attacker can gain privileged ac...
CVE-2016-6551Intellian Satellite TV antennas t-Series and v-Series, firmware version 1.07, uses non-random default credentials of: ft...
CVE-2016-6549The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications...
CVE-2016-6548The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated ...
CVE-2016-6547The Zizai Tech Nut mobile app stores the account password used to authenticate to the cloud API in cleartext in the cach...
CVE-2016-6546The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding ...
CVE-2016-6545Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST para...
CVE-2016-6544getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now